A ransomware group identified as Rhysida has initiated an auction for data stolen from Berlin government agencies, following the city’s refusal to meet ransom demands. The group is offering 5.79 terabytes of compromised data, including 46,500 contracts, emails, phone numbers, passwords, and classified information, with a starting bid of 30 bitcoins, equivalent to approximately $77,622.
The auction was launched on the group’s website, where a countdown timer indicated slightly less than seven days remaining for bids. The announcement came one day after Berlin authorities received a ransom demand, which was disclosed in a joint statement by Mayor Kai Wegner and Interior Senator Iris Spranger. In the statement, the officials declared that the state of Berlin would not submit to extortion, reaffirming a firm stance against ransom payments.
Kai Wegner stated in a press conference that authorities could not yet provide details on the full scope of the breach, as investigations into the extent of the compromised data remained ongoing. Iris Spranger separately confirmed that the city’s electoral infrastructure had not been affected and that, according to security authorities, no election-related data had been compromised. The cyberattack occurred less than a month before Berlin’s city-state elections scheduled for September 20, 2026.
Cybercrime research platform eCrime.ch reports that the Rhysida group has claimed responsibility for nearly 280 attacks since its emergence in June 2023. The group is believed to operate from Russia or Eastern Europe, though its exact origins remain unverified.












